|
|
||||||||||||||||
|
|
|
|
|
|||||||||||||
|
|
Centers for Disease Control and Prevention Division of Cancer Prevention and Control 4770 Buford Hwy, NE MS K-64 Atlanta, GA 30341-3717 Call: 1 (800) CDC-INFO TTY: 1 (888) 232-6348 FAX: (770) 488-4760 E-mail: cdcinfo@cdc.gov |
|
|
|
The CDC Certification and Accreditation (C&A) Process
All information systems developed by CDC's National Program of Cancer Registries (NPCR) adhere to the standards defined by the National Institute of Standards and Technology (NIST) in Special Publication 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems (PDF-738KB). This publication provides guidelines for the security certification and accreditation of information systems supporting the executive agencies of the federal government, and these guidelines apply to all federal information systems except national security systems. The CDC C&A process ensures that all information systems made available by CDC to implement the NPCR meet or exceed the C&A accreditation standards when operated with appropriate management review. It requires ongoing security control monitoring and reaccreditations periodically or when there is a significant change to an information system or its environment.
Sample CDC C&A ChecklistA generic version of NIST's checklist (DOC-687KB) for an application that is considered a moderate threat to go through the the CDC C&A process is available. It provides the minimum checklist of controls reviewed for the application reviewed. Web Plus Security Features and RecommendationsWeb Plus is a highly secure application that can be used to transmit confidential patient data between reporting locations and a central registry safely over the Internet. See Security Features in Web Plus for basic information and Maximizing Data Security in Web Plus for technical information.
Page last reviewed: May 4, 2009
Page last updated: October 20, 2009 Content source: Division of Cancer Prevention and Control, National Center for Chronic Disease Prevention and Health Promotion |
|
|
|
|
||||||||||||
|